Appl. No. 10/711,954 

Amdt. Dated February 15, 2008 

Reply to Office Action of November 16, 2007 

Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

1 . (Previously Amended) A method to protect a file system from a viral infection, 
comprising: 

flagging a program on a computer as being suspect for possibly containing a virus in 
response to at least one of: 

opening a local file on a local file system of the computer to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 

the program reading or opening itself and the program attempting to write or 
append any content to the shared file on the shared or network file system or to write or append any 
content to the local file on the local file system; 

the program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the program attempting to write or append a remote file to the local file 

system; 

storing a filename and a location where the local or shared file is copied or written in 
response to the local or shared file being copied or written by the program. 

2. (Previously Presented) The method of claim 1, further comprising inhibiting a write or 
append operation associated with the program in response to flagging the program. 

3. (Original) The method of claim 1, further comprising monitoring all file operations 
associated with the program in response to the program not being in a safe list. 
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4. (Original) The method of claim 1, further comprising permitting selected read and write 
operations in response to a predefined rules table. 

5. (Original) The method of claim 1, further comprising sending an alert in response to 
flagging the program. 

6. (Canceled) 

7. (Original) The method of claim 1, further comprising sending an alert to a network 
monitoring system in response to flagging the program. 

8. (Original) The method of claim 1, further comprising logging any file system operations 
including recording a filename and a location where the local or shared file is written. 

9. (Previously Amended) A method to protect a file system from a viral infection, 
comprising: 

allowing a security level to be set; 

monitoring predetermined file system operations associated with a program; and 
logging any predetermined file system operations associated with the program 

including recording a filename and a location where a file is written in response to the file being 

written. 

10. (Original) The method of claim 9, further comprising selecting the program for 
monitoring in response to the program not being on a safe list. 

1 1 . (Original) The method of claim 10, further comprising logging any file system 
operations associated with any programs on the safe list. 

12. (Original) The method of claim 9, further comprising receiving a notification that the 
program intends to perform one of the predetermined file system operations. 
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13. (Previously Presented) The method of claim 9, further comprising following a 
predefined procedure in response to the level of security set. 

14. (Original) The method of claim 9, further comprising flagging the program in response 
to the program attempting to perform one of the predetermined file system operations. 

15. (Original) The method of claim 14, further comprising flagging the program in 
response to at least one of: 

the program opening a local file on a local file system to perform a read operation 
and opening a shared file on a shared or network file system to perform a write or append operation 
with the local file; 

the program reading or opening itself and the program attempting to write or append 
any content to the shared file on the shared or network file system or to write or append any content 
to the local file on the local file system; 

the program attempting to write or append the local file to the shared or network file 
system and preserve a filename of the local file in the shared or network file system; and 

the program attempting to write or append a remote file to the local file system. 

16. (Original) The method of claim 14 , further comprising inhibiting any predetermined 
file system operations associated with the program in response to the program being flagged. 

17. (Original) The method of claim 9, further comprising sending an alert in response to the 
program attempting to perform any predetermined file system operations. 

18. (Original) The method of claim 17, further comprising sending the alert to a network 
monitoring system. 

19. (Original) The method of claim 9, further comprising presenting an alert to a user for 
approval before the predetermined file system operation is performed by the program. 
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20. (Previously Amended) The method of claim 9, further comprising requiring approval 
before performing any predetermined file system operations associated with the program in 
response to the program not being on a safe list. 

21.-44. Cancelled. 
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